mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-08 02:27:37 +00:00
Merge pull request #3139 from akhilmhdh/fix/shared-link-min-check
feat: added min check for secret sharing
This commit is contained in:
@@ -34,6 +34,25 @@ export const secretSharingServiceFactory = ({
|
|||||||
orgDAL,
|
orgDAL,
|
||||||
kmsService
|
kmsService
|
||||||
}: TSecretSharingServiceFactoryDep) => {
|
}: TSecretSharingServiceFactoryDep) => {
|
||||||
|
const $validateSharedSecretExpiry = (expiresAt: string) => {
|
||||||
|
if (new Date(expiresAt) < new Date()) {
|
||||||
|
throw new BadRequestError({ message: "Expiration date cannot be in the past" });
|
||||||
|
}
|
||||||
|
|
||||||
|
// Limit Expiry Time to 1 month
|
||||||
|
const expiryTime = new Date(expiresAt).getTime();
|
||||||
|
const currentTime = new Date().getTime();
|
||||||
|
const thirtyDays = 30 * 24 * 60 * 60 * 1000;
|
||||||
|
if (expiryTime - currentTime > thirtyDays) {
|
||||||
|
throw new BadRequestError({ message: "Expiration date cannot be more than 30 days" });
|
||||||
|
}
|
||||||
|
|
||||||
|
const fiveMins = 5 * 60 * 1000;
|
||||||
|
if (expiryTime - currentTime < fiveMins) {
|
||||||
|
throw new BadRequestError({ message: "Expiration time cannot be less than 5 mins" });
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
const createSharedSecret = async ({
|
const createSharedSecret = async ({
|
||||||
actor,
|
actor,
|
||||||
actorId,
|
actorId,
|
||||||
@@ -49,18 +68,7 @@ export const secretSharingServiceFactory = ({
|
|||||||
}: TCreateSharedSecretDTO) => {
|
}: TCreateSharedSecretDTO) => {
|
||||||
const { permission } = await permissionService.getOrgPermission(actor, actorId, orgId, actorAuthMethod, actorOrgId);
|
const { permission } = await permissionService.getOrgPermission(actor, actorId, orgId, actorAuthMethod, actorOrgId);
|
||||||
if (!permission) throw new ForbiddenRequestError({ name: "User is not a part of the specified organization" });
|
if (!permission) throw new ForbiddenRequestError({ name: "User is not a part of the specified organization" });
|
||||||
|
$validateSharedSecretExpiry(expiresAt);
|
||||||
if (new Date(expiresAt) < new Date()) {
|
|
||||||
throw new BadRequestError({ message: "Expiration date cannot be in the past" });
|
|
||||||
}
|
|
||||||
|
|
||||||
// Limit Expiry Time to 1 month
|
|
||||||
const expiryTime = new Date(expiresAt).getTime();
|
|
||||||
const currentTime = new Date().getTime();
|
|
||||||
const thirtyDays = 30 * 24 * 60 * 60 * 1000;
|
|
||||||
if (expiryTime - currentTime > thirtyDays) {
|
|
||||||
throw new BadRequestError({ message: "Expiration date cannot be more than 30 days" });
|
|
||||||
}
|
|
||||||
|
|
||||||
if (secretValue.length > 10_000) {
|
if (secretValue.length > 10_000) {
|
||||||
throw new BadRequestError({ message: "Shared secret value too long" });
|
throw new BadRequestError({ message: "Shared secret value too long" });
|
||||||
@@ -100,17 +108,7 @@ export const secretSharingServiceFactory = ({
|
|||||||
expiresAfterViews,
|
expiresAfterViews,
|
||||||
accessType
|
accessType
|
||||||
}: TCreatePublicSharedSecretDTO) => {
|
}: TCreatePublicSharedSecretDTO) => {
|
||||||
if (new Date(expiresAt) < new Date()) {
|
$validateSharedSecretExpiry(expiresAt);
|
||||||
throw new BadRequestError({ message: "Expiration date cannot be in the past" });
|
|
||||||
}
|
|
||||||
|
|
||||||
// Limit Expiry Time to 1 month
|
|
||||||
const expiryTime = new Date(expiresAt).getTime();
|
|
||||||
const currentTime = new Date().getTime();
|
|
||||||
const thirtyDays = 30 * 24 * 60 * 60 * 1000;
|
|
||||||
if (expiryTime - currentTime > thirtyDays) {
|
|
||||||
throw new BadRequestError({ message: "Expiration date cannot exceed more than 30 days" });
|
|
||||||
}
|
|
||||||
|
|
||||||
const encryptWithRoot = kmsService.encryptWithRootKey();
|
const encryptWithRoot = kmsService.encryptWithRootKey();
|
||||||
const encryptedSecret = encryptWithRoot(Buffer.from(secretValue));
|
const encryptedSecret = encryptWithRoot(Buffer.from(secretValue));
|
||||||
|
|||||||
Reference in New Issue
Block a user